Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the system time (which is available from HTTP response headers), a call to the built-in rand() function, and the PID.
References
| Link | Resource |
|---|---|
| https://metacpan.org/dist/Maypole/source/lib/Maypole/Session.pm#L43 | Issue Tracking |
Configurations
Configuration 1 (hide)
|
History
10 Mar 2026, 15:07
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:teejay:maypole:2.111:*:*:*:*:perl:*:* cpe:2.3:a:teejay:maypole:2.121:*:*:*:*:perl:*:* |
04 Mar 2026, 02:26
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://metacpan.org/dist/Maypole/source/lib/Maypole/Session.pm#L43 - Issue Tracking | |
| First Time |
Teejay
Teejay maypole |
|
| CPE | cpe:2.3:a:teejay:maypole:*:*:*:*:*:perl:*:* |
18 Feb 2026, 17:52
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
17 Feb 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
16 Feb 2026, 22:22
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-16 22:22
Updated : 2026-03-10 15:07
NVD link : CVE-2025-15578
Mitre link : CVE-2025-15578
CVE.ORG link : CVE-2025-15578
JSON object : View
Products Affected
teejay
- maypole
CWE
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
